Rockwell’s latest patch set matters, but the operational problem is the older, already-exploited trust path that is still sitting in deployed OT gear. The company confirmed in-the-wild abuse of CVE-2021-22681, even as its new advisories for Logix, CompactLogix, ControlLogix, Flex I/O, RSLinx, and FactoryTalk have not yet been seen targeted.
The new fixes cover DoS bugs in controllers, authentication-bypass and password-change issues in FactoryTalk Historian Site Edition and Flex I/O dual-port Ethernet/IP adapters, and an improper API authorization flaw in FactoryTalk Analytics PavilionX. For plant and critical-infrastructure teams, the sharper risk is still legacy engineering and controller assets that trust device identity or session state and may be exposed through a path attackers already know works.
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP Summary Successful exploitation of this vulnerability could cause a denial-of-service condition that may result in a major nonrecoverable fault (MNRF).
Rockwell Automation RSLinx Summary Successful exploitation of this vulnerability can lead to a denial of service, where the application will become unresponsive and will not recover on its own.
Rockwell Automation CompactLogix Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition.